Loading vulnerability details…
CVSS v3.1
N/A
EPSS
2.18%
Published
Mar 27, 2019
Modified
Nov 20, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
Weaknesses (CWE)
Affected Products (1)
References (6)